UBUNTU-CVE-2017-12424
Dashboard / Vulnerabilities / UBUNTU-CVE-2017-12424
UBUNTU-CVE-2017-12424
Summary:
Details: In shadow before 4.5, the newusers tool could be made to manipulate internal data structures in ways unintended by the authors. Malformed input may lead to crashes (with a buffer overflow or other memory corruption) or other unspecified behaviors. This crosses a privilege boundary in, for example, certain web-hosting environments in which a Control Panel allows an unprivileged user account to create subaccounts.
References: https://ubuntu.com/security/CVE-2017-12424, https://ubuntu.com/security/notices/USN-5254-1, https://www.cve.org/CVERecord?id=CVE-2017-12424
Affected packages
Package
Name: shadow
Purl: pkg:deb/ubuntu/shadow@1:4.1.5.1-1ubuntu9.5+esm1?arch=source&distro=trusty/esm
Affected ranges
Type: ECOSYSTEM
Events:
